PyDFIR / pyDFIRRam
PyDFIRRam is a Python library leveraging Volatility 3 to simplify and enhance memory forensics. It streamlines the research, parsing, and analysis of memory dumps, allowing users to focus on data rather than commands.
☆25Updated 5 months ago
Alternatives and similar repositories for pyDFIRRam:
Users that are interested in pyDFIRRam are comparing it to the libraries listed below
- A python script to automatically list vulnerable Windows ACEs/ACLs.☆48Updated 2 months ago
- Repository of Yara Rules☆100Updated this week
- Dissecting and Defeating Ransomware's Evasion Tactics Defcon 32☆11Updated 6 months ago
- All kinds of tiny shells☆58Updated 2 years ago
- APT hub, It help's research to collect information and data on the latest APT activities. It collects data on APT profiles, IOCs(1 yr), a…☆48Updated 3 months ago
- DFIR ORC PARSER PROJECT☆25Updated last month
- ☆105Updated 7 months ago
- GeoWordlists is a tool to generate wordlists of passwords containing cities at a defined distance around the client city.☆145Updated last week
- Python tool to check rootkits in Windows kernel☆192Updated 2 weeks ago
- Memory mapping profiles for forensic analysis using volatility 2☆46Updated 2 years ago
- Ansible + Vagrant + Hyper-V + Vulnerable AD 😎☆90Updated 6 months ago
- ☆134Updated 6 months ago
- ☆132Updated last year
- DFIR project to collect and analyze events in Google Workspace☆13Updated 10 months ago
- ACEshark is a utility designed for rapid extraction and analysis of Windows service configurations and Access Control Entries, eliminatin…☆85Updated last month
- VM Lab for security☆9Updated 11 months ago
- Configuration Extractors for Malware☆91Updated 3 weeks ago
- ☆55Updated 4 months ago
- A ProcessMonitor visualization application written in rust.☆178Updated last year
- The ldap2json script allows you to extract the whole LDAP content of a Windows domain into a JSON file.☆126Updated 3 months ago
- Basic reverse shell in C using socket() with complete explanation☆65Updated last year
- Cheat sheet to detect and remove linux kernel rootkit☆48Updated 2 months ago
- Unprotect is a collaborative platform dedicated to uncovering and documenting malware evasion techniques. We invite you to join us in thi…☆154Updated last month
- Find potential DLL Sideloads on your windows computer☆175Updated last month
- Breizh CTF 2024 - Challenges☆13Updated 8 months ago
- linikatz is a tool to attack AD on UNIX☆142Updated last year